What being locked out of WordPress admin can mean
Start by noting exactly what happens at /wp-login.php or /wp-admin/. An "incorrect password" message, redirect loop, blank page, critical error and security lockout are different faults and need different recovery routes.
If the public website still works, avoid broad changes to core files. The safest recovery route depends on what access you still have: email, another administrator account, hosting file access, database access or WP-CLI over SSH.
Never send your WordPress password, hosting password or database password by email or in a support ticket. If another person needs access, create or reset a separate account instead.
Common reasons wp-admin stops working
A forgotten password is only one possibility. A security plugin may temporarily block an IP after repeated login attempts, require two-factor authentication, or change the login path.
- Password reset email never arrives. The site's outgoing email may be failing or the account email may no longer be correct.
- Cookies or redirects are broken. A stale browser cookie, wrong WordPress URL, HTTPS change or proxy rule can send the login request in circles.
- A security plugin blocks access. Rate limits, firewall rules or lost two-factor credentials can stop a valid administrator.
- A plugin causes a fatal error. The front end may work while wp-admin fails.
- The account changed. The administrator role, email address or password hash may have been altered.
If the lockout followed an unexpected account change or you suspect compromise, treat it as a security incident rather than just a password problem. Review our website security guidance once access is restored.
How to regain access to WordPress safely
Use the least invasive route first. Before editing files or the database, take a full backup of both files and database.
- Rule out a browser problem. Open the normal /wp-login.php address in a private window, then clear cookies for the site if that works.
- Use Lost your password? If the reset email arrives, set a new strong, unique password and sign in normally.
- Use another administrator account. A second trusted admin can reset your password from Users and check whether a security plugin has blocked your account or IP.
- Prefer WP-CLI when server access is available. It uses WordPress itself to reset the account password. The following command generates and displays a new password for the named user:
wp user reset-password username --show-passwordStore the generated password securely and change it again after login if your operational policy requires it.
If WP-CLI is unavailable, phpMyAdmin is a fallback. Find the actual users table, which may not be named wp_users if a custom prefix is used. Edit only the intended user's user_pass field, enter a new strong temporary password and choose the MD5 function. WordPress accepts this legacy reset format for recovery and replaces it with its stronger current hash after a successful login.
If a security plugin itself is blocking access and you have verified file access, rename that plugin's directory inside wp-content/plugins rather than deleting it. Try the login again, then restore the folder name and review the plugin configuration before reactivating it.
When to stop and get help with a WordPress lockout
Stop if you cannot identify the correct database, table prefix or administrator account, or if the site shows a new error after a recovery change. Do not create database users, edit WordPress core files or delete wp-config.php as a shortcut.
Get technical help if the account was altered without your knowledge, malware is suspected, or the site has both login and database errors. Recovering access does not remove the underlying cause.
Our Emergency Fix is £249 per incident with a response within 2 working hours. Care plans start from £59 a month for ongoing maintenance and support.